Home Malware Programs Worms Pushbot.RX

Pushbot.RX

Posted: December 8, 2010

Threat Metric

Threat Level: 5/10
Infected PCs: 68
First Seen: December 8, 2010
OS(es) Affected: Windows

Aliases

Generic20.QBO [AVG]Worm.Win32.Carrier [Ikarus]Trojan/Win32.Jorik [AhnLab-V3]Win32/LolBot.EH [eTrust-Vet]TR/Jorik.Lolbot.IX [AntiVir]UnclassifiedMalware [Comodo]Trojan.Win32.Jorik.Lolbot.ix [Kaspersky]Packed.Generic.307 [Symantec]Trojan.Jorik.Lolbot.ix [CAT-QuickHeal]Generic20.ABKO [AVG]W32/Oficla.CWK!tr [Fortinet]Gen.Trojan.Heur [Ikarus]Trojan/Win32.Oficla.gen [Antiy-AVL]TR/Oficla.cwk [AntiVir]TrojWare.Win32.Trojan.Agent.Gen [Comodo]
More aliases (66)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%PUBLIC%\rundll32.exe File name: rundll32.exe
Size: 93.71 KB (93711 bytes)
MD5: 461f789cab5ac3234b0f4909e593efcd
Detection count: 75
File type: Executable File
Mime Type: unknown/exe
Path: %PUBLIC%
Group: Malware file
Last Updated: December 8, 2010
%APPDATA%\winlogon.exe File name: winlogon.exe
Size: 262.14 KB (262144 bytes)
MD5: fa5efcea11c3d190111c84a3a6761354
Detection count: 44
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: December 9, 2010
%APPDATA%\mssend2\svcnost.exe File name: svcnost.exe
Size: 102.4 KB (102400 bytes)
MD5: cb463cdacc0b4d08935b612d999ee4f0
Detection count: 12
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\mssend2
Group: Malware file
Last Updated: December 9, 2010
%APPDATA%\winIogon.exe File name: winIogon.exe
Size: 252.41 KB (252416 bytes)
MD5: 0d92ad1ef4b8ca115e6b757103617c03
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: December 9, 2010
%WINDIR%\system32\atmlib32.dll File name: atmlib32.dll
Size: 262.14 KB (262144 bytes)
MD5: 38c589d8d5bf1af614ed642a7c82650e
Detection count: 5
File type: Dynamic link library
Mime Type: unknown/dll
Path: %WINDIR%\system32
Group: Malware file
Last Updated: December 9, 2010
Loading...